Vulnerability Details CVE-2020-15776
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could impose an arbitrary value for this token, allowing them to perform cross-site request forgery.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2020-15776
-
cpe:2.3:a:gradle:enterprise:2018.2
-
cpe:2.3:a:gradle:enterprise:2018.5
-
cpe:2.3:a:gradle:enterprise:2018.5.1
-
cpe:2.3:a:gradle:enterprise:2018.5.2
-
cpe:2.3:a:gradle:enterprise:2018.5.3
-
cpe:2.3:a:gradle:enterprise:2020.1
-
cpe:2.3:a:gradle:enterprise:2020.2
-
cpe:2.3:a:gradle:enterprise:2020.2.4